---
title: "Assets are what we pentest"
description: "An asset is a either a software component of value, such as a web application or API, or a network environment. Once you’ve created an asset, you can launch pentests for it."
canonical_url: "https://docs.cobalt.io/articles/assets-are-what-we-pentest-09RgsvQ7zv"
md_url: "https://docs.cobalt.io/articles/assets-are-what-we-pentest-09RgsvQ7zv.md"
---
# Assets are what we pentest

:::info
An asset is a either a software component of value, such as a web application or API, or a network environment. Once you’ve created an asset, you can launch pentests for it.

:::

## Create an Asset

**Best practices for creating an asset**:

* Describe your asset as clearly as possible.
* Add a product walk-through and asset documentation using the [provided templates](https://cobalt-io.brainfish.ai/en-us/articles/create-an-asset-9P1WPENeIC).
* Keep your assets up to date.
* Start creating or editing your asset before creating a pentest. You can reuse the asset for future pentests.
* Use tags to map your assets to external systems.

**[Read the Guide](https://cobalt-io.brainfish.ai/en-us/articles/create-an-asset-9P1WPENeIC)**

## View and Manage Assets    

 ![](https://docs.cobalt.io/api/attachments.redirect?id=b99e0696-9704-497d-a03a-773332cb4312 " =1012x537")

On the **Assets** page, you can:

* [Preview risk advisories](https://cobalt-io.brainfish.ai/en-us/articles/risk-advisories-ayLKDrTIgu). To preview a summary of potential vulnerabilities based on the [Common Vulnerabilities and Exposures (CVE)](https://www.cve.org/) standard, point to the number under **Risk Advisory**. To navigate to the detailed list, select the number.
* View the [Aggregated Risk](https://cobalt-io.brainfish.ai/en-us/articles/glossary-YfTMKeZ1VM) for the last pentest. To navigate to the **[Insights](https://docs.cobalt.io/en-us/articles/insights-r4Jw78EcgA?region=US)** page, select the number.
* Sort assets in ascending or descending order.
* Manage assets. Select the three-dot icon • • • under **Action**, and then select the desired option:
  * **Create a Pentest** for this asset
  * **Edit Asset** to modify [asset details](https://cobalt-io.brainfish.ai/en-us/articles/create-an-asset-9P1WPENeIC)
  * **Delete Asset**, if it doesn’t have associated pentests
  * Navigate to the **Latest Pentest Report**


:::info
**Note**

To analyze the security posture of your assets over time and observe trends, navigate to [Cobalt Insights](https://docs.cobalt.io/en-us/articles/insights-r4Jw78EcgA?region=US).

:::

### Asset Details Page

On the asset details page, you can:

* Create a pentest for this asset
* Edit [asset details](https://cobalt-io.brainfish.ai/en-us/articles/create-an-asset-9P1WPENeIC)
* Delete the asset, if it doesn’t have associated pentests
* View associated pentests
* Preview [risk advisories](https://cobalt-io.brainfish.ai/en-us/articles/risk-advisories-ayLKDrTIgu) for this asset


:::info
**Note**

Once you’ve defined an asset, you can launch pentests for it. You don’t need to create this asset again for each new pentest. When needed, update the asset description, and attach new documents.

:::

 ![](https://docs.cobalt.io/api/attachments.redirect?id=0f95b8f1-c0b8-46c6-9798-3ad47b9f27f8)

## Access and Permissions

Only Organization Owners and Members can create an asset.

Pentest Team Members don’t have access to the **Assets** page.

* They can view and edit assets that are linked to pentests they collaborate on.
* They may not be allowed to [add attachments](https://cobalt-io.brainfish.ai/en-us/articles/create-an-asset-9P1WPENeIC#h-attachments) to an asset. An Organization Owner or Member of their company or a Cobalt Customer Success Manager can assist in this case.

For more information about user permissions, see [User Roles and Permissions](https://cobalt-io.brainfish.ai/en-us/articles/user-roles-and-permissions-oCij6uRrUR).

## Frequently Asked Questions

**Can I attach two or more assets to a pentest?**

No, you can only launch a pentest for a **single asset**.

If your asset has multiple [methodologies](https://cobalt-io.brainfish.ai/en-us/articles/cobalt-methodologies-LTfYQiQvzV), such as Web + API, you can choose a combined methodology. If the combination is not available, such as for Mobile + External Network, do the following:


1. Select one of the available asset types.
2. Let your CSM know so that we can select pentesters with the appropriate expertise.

**I want to test two scopes. How many assets should I set up?**

You can only launch a pentest for a **single asset**. Let’s rephrase this question: how many pentests should you launch for two scopes?

For assets of multiple types, you may want to **launch one or more pentests**, depending on the characteristics of your software.

For example, if your asset combines a web and mobile application, you may want us to test them together, in **one pentest**, if:

* The two applications share some of the same code and functionalities.
* One [pentest report](https://cobalt-io.brainfish.ai/en-us/articles/reports-YkC2da1roR) is sufficient for your purposes.
* One team is responsible for both applications.

Otherwise, you may need to set up **two pentests** to get more granular results. You can run multiple pentests for the same asset.
